Vulnerabilities > Atlassian > Medium

DATE CVE VULNERABILITY TITLE RISK
2020-02-06 CVE-2019-20403 Unspecified vulnerability in Atlassian Jira Server
The API in Atlassian Jira Server and Data Center before version 8.6.0 allows remote attackers to determine if a Jira project key exists or not via an information disclosure vulnerability.
network
low complexity
atlassian
5.3
2020-02-06 CVE-2019-20402 Unspecified vulnerability in Atlassian Jira
Support zip files in Atlassian Jira Server and Data Center before version 8.6.0 could be downloaded by a System Administrator user without requiring the user to re-enter their password via an improper authorization vulnerability.
network
low complexity
atlassian
4.9
2020-02-06 CVE-2019-20401 Cross-Site Request Forgery (CSRF) vulnerability in Atlassian Jira Server
Various installation setup resources in Jira before version 8.5.2 allow remote attackers to configure a Jira instance, which has not yet finished being installed, via Cross-site request forgery (CSRF) vulnerabilities.
network
low complexity
atlassian CWE-352
6.5
2020-02-06 CVE-2019-20106 Incorrect Default Permissions vulnerability in Atlassian products
Comment properties in Atlassian Jira Server and Data Center before version 7.13.12, from 8.0.0 before version 8.5.4, and 8.6.0 before version 8.6.1 allows remote attackers to make comments on a ticket to which they do not have commenting permissions via a broken access control bug.
network
low complexity
atlassian CWE-276
4.3
2019-12-19 CVE-2019-15006 Improper Control of Dynamically-Managed Code Resources vulnerability in Atlassian Confluence and Confluence Server
There was a man-in-the-middle (MITM) vulnerability present in the Confluence Previews plugin in Confluence Server and Confluence Data Center.
network
high complexity
atlassian CWE-913
6.5
2019-12-18 CVE-2019-15013 Missing Authorization vulnerability in Atlassian Jira
The WorkflowResource class removeStatus method in Jira before version 7.13.12, from version 8.0.0 before version 8.4.3, and from version 8.5.0 before version 8.5.2 allows authenticated remote attackers who do not have project administration access to remove a configured issue status from a project via a missing authorisation check.
network
low complexity
atlassian CWE-862
4.3
2019-12-17 CVE-2019-15011 Incorrect Default Permissions vulnerability in Atlassian Application Links
The ListEntityLinksServlet resource in Application Links before version 5.0.12, from version 5.1.0 before version 5.2.11, from version 5.3.0 before version 5.3.7, from version 5.4.0 before 5.4.13, and from version 6.0.0 before 6.0.5 disclosed application link information to non-admin users via a missing permissions check.
network
low complexity
atlassian CWE-276
4.3
2019-12-17 CVE-2017-18107 Cross-Site Request Forgery (CSRF) vulnerability in Atlassian Crowd
Various resources in the Crowd Demo application of Atlassian Crowd before version 3.1.1 allow remote attackers to modify add, modify and delete users & groups via a Cross-site request forgery (CSRF) vulnerability.
network
low complexity
atlassian CWE-352
6.5
2019-12-11 CVE-2019-15009 Unspecified vulnerability in Atlassian Crucible
The /json/profile/removeStarAjax.do resource in Atlassian Fisheye and Crucible before version 4.8.0 allows remote attackers to remove another user's favourite setting for a project via an improper authorization vulnerability.
network
low complexity
atlassian
4.3
2019-12-11 CVE-2019-15008 Cross-site Scripting vulnerability in Atlassian Crucible
The /plugins/servlet/branchreview resource in Atlassian Fisheye and Crucible before version 4.7.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the reviewedBranch parameter.
network
low complexity
atlassian CWE-79
6.1